RULE(RULE ID:339138)

Rule General Information
Release Date: 2025-06-25
Rule Name: Yonyou GRP U8 listSelectDialogServlet SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Yonyou GRP-U8 Administrative and Institutional Financial Management Software is a new-generation product launched by Yonyou for national e-government, based on cloud computing technology, and is one of the most professional government financial management systems in China. A SQL injection vulnerability exists in the listSelectDialogServlet interface due to insufficient input validation. Attackers may inject malicious SQL statements to perform unauthorized operations, leading to information disclosure and potentially compromising server control.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.